Question 131

A penetration tester gains initial access to a Windows workstation on a client's network. The tester wants to determine the next target but does not want to install software on the workstation.
Which of the following is the best tool to list potential targets?
  • Question 132

    A penetration tester is conducting a vulnerability scan. The tester wants to see any vulnerabilities that may be visible from outside of the organization. Which of the following scans should the penetration tester perform?
  • Question 133

    SIMULATION
    A previous penetration test report identified a host with vulnerabilities that was successfully exploited. Management has requested that an internal member of the security team reassess the host to determine if the vulnerability still exists.

    Part 1:
    . Analyze the output and select the command to exploit the vulnerable service.
    Part 2:
    . Analyze the output from each command.
    * Select the appropriate set of commands to escalate privileges.
    * Identify which remediation steps should be taken.

    Question 134

    You are a penetration tester reviewing a client's website through a web browser.
    INSTRUCTIONS
    Review all components of the website through the browser to determine if vulnerabilities are present.
    Remediate ONLY the highest vulnerability from either the certificate, source, or cookies.
    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.






    Question 135

    The delivery of a penetration test within an organization requires defining specific parameters regarding the nature and types of exercises that can be conducted and when they can be conducted. Which of the following BEST identifies this concept?